瑞星卡卡安全论坛技术交流区反病毒/反流氓软件论坛 【求助】中毒了,请高手帮帮忙了,谢谢!

12   1  /  2  页   跳转

【求助】中毒了,请高手帮帮忙了,谢谢!

【求助】中毒了,请高手帮帮忙了,谢谢!

开机后会出现一个错误窗口:
fatal execution engine error (0x7927baca)
关了后又出现另一窗口:
标题:setup error
内容:failed to load resources from resoursce file please check your setup

现在连卡卡和SER都没法用了,只要一点击就会自动关机。所以日志扫不出来。
最后编辑2007-03-21 12:47:42
分享到:
gototop
 

【回复“求知而来”的帖子】
fatal execution engine error (0x7927baca)——致命性执行引擎错误(0x7927baca)
failed to load resources from resoursce file please check your setup——————从资源文件加载资源失败,请检查您的设置。
gototop
 

进安全模式试试
把SRENG的后缀改成.COM试试.
看不到日志,很多问题不好说啊
gototop
 

为什么SRE不能用呢?连日志都扫不出,还有连安全模式都进不了,有什么办法吗?
gototop
 

用瑞星杀了十多个毒
gototop
 

引用:
【求知而来的贴子】为什么SRE不能用呢?连日志都扫不出,还有连安全模式都进不了,有什么办法吗?
………………

这种情况已不算奇怪。
最近见到一个病毒,用IFEO劫持,将若干杀软以及大多数手动查杀病毒工具定向到病毒程序自身。中了之后,如果没有第三方注册表编辑器,较难搞掂。
gototop
 

那就是说只有重装系统了
gototop
 

高手来帮帮忙呀
gototop
 

07年病毒太厉害了,现在貌似没有套完善的处理措施,建议你重做系统后做好GHOST备份,有条件的话直接刻成光盘保存吧,这方法比较简单
gototop
 

[CODE]

2007-03-20,21:34:58

System Repair Engineer 2.3.13.690
Smallfrogs (http://www.KZTechs.com)

Windows XP Professional Service Pack 1 (Build 2600)
- 管理权限用户 - 完整功能

以下内容被选中:
    所有的启动项目(包括注册表、启动文件夹、服务等)
    浏览器加载项
    正在运行的进程(包括进程模块信息)
    文件关联
    Winsock 提供者
    Autorun.inf
    HOSTS 文件


启动项目
注册表
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    <MSMSGS><"C:\Program Files\Messenger\msmsgs.exe" /background>  [(Verified)Microsoft Corporation]
    <ctfmon.exe><C:\windows\System32\ctfmon.exe>  [(Verified)Microsoft Corporation]
[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <load><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    <miniqqlive><"C:\Program Files\Tencent\QQLive\MiniQQLive.exe">  [N/A]
    <WinampAgent><"C:\Program Files\Winamp\Winampa.exe">  [N/A]
    <TkBellExe><realsched.exe -osboot>  [N/A]
    <SysExplr><C:\Herosoft\HeroV8\SysExplr.EXE>  [N/A]
    <PHIME2002ASync><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC>  [(Verified)Microsoft Corporation]
    <PHIME2002A><C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName>  [(Verified)Microsoft Corporation]
    <NeroCheck><C:\WINDOWS\System32\\NeroCheck.exe>  [Ahead Software Gmbh]
    <IMJPMIG8.1><"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32>  [(Verified)Microsoft Corporation]
    <RavTask><"C:\Program Files\Rising\Rav\RavTask.exe" -system>  [Beijing Rising Technology Co., Ltd.]
    <RfwMain><"C:\Program Files\Rising\Rfw\rfwmain.exe" -Startup>  [Beijing Rising Technology Co., Ltd.]
    <runeip><C:\Program Files\Rising\KakaToolBar\runiep.exe>  [N/A]
    <z4z5><C:\windows\alga.exe>  [N/A]
    <KernelFaultCheck><%systemroot%\system32\dumprep 0 -k>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <shell><Explorer.exe>  [(Verified)Microsoft Corporation]
    <Userinit><C:\WINDOWS\system32\userinit.exe,>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    <AppInit_DLLs><>  [N/A]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    <UIHost><logonui.exe>  [(Verified)Microsoft Corporation]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    <{32CD708B-60A7-4C00-9377-D73EAA495F0F}><C:\windows\system32\RavExt.dll>  [Beijing Rising Technology Co., Ltd.]
    <{36CD708B-6077-4C02-9377-D73EAA495A0F}><C:\WINDOWS\WinHttp.dll>  [Microsoft Corporation]
    <{FEDCBA98-FEDC-FEDC-FEDC-FEDCBA987654}><C:\windows\System32\RWBCHMRS.dll>  [N/A]

==================================
启动文件夹
[AutoCAD 启动加速器]
  <C:\Documents and Settings\All Users\「开始」菜单\程序\启动\AutoCAD 启动加速器.lnk --> C:\PROGRA~1\COMMON~1\AUTODE~1\ACSTAR~1.EXE [Autodesk, Inc]><N>
[腾讯QQ]
  <C:\Documents and Settings\liu\「开始」菜单\程序\启动\腾讯QQ.lnk --> C:\PROGRA~1\Tencent\QQ\QQ.exe [TENCENT]><N>

==================================
服务
[ASP.NET State Service / aspnet_state][Stopped/Manual Start]
  <C:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe><Microsoft Corporation>
[Autodesk Licensing Service / Autodesk Licensing Service][Stopped/Manual Start]
  <"C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe"><Autodesk, Inc.>
[Human Interface Device Access / HidServ][Stopped/Disabled]
  <C:\windows\System32\svchost.exe -k netsvcs-->%SystemRoot%\System32\hidserv.dll><N/A>
[Machine Debug Manager / MDM][Running/Auto Start]
  <"C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe"><Microsoft Corporation>
[Rising Proxy  Service / RfwProxySrv][Stopped/Manual Start]
  <c:\program files\rising\rfw\rfwproxy.exe><Beijing Rising Technology Co., Ltd.>
[Rising Personal Firewall Service / RfwService][Running/Auto Start]
  <c:\program files\rising\rfw\rfwsrv.exe><Beijing Rising Technology Co., Ltd.>
[Rising Process Communication Center / RsCCenter][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\CCenter.exe"><Beijing Rising Technology Co., Ltd.>
[Rising RealTime Monitor / RsRavMon][Running/Auto Start]
  <"C:\Program Files\Rising\Rav\Ravmond.exe"><Beijing Rising Technology Co., Ltd.>
[Portable Media Serial Number Service / WmdmPmSN][Stopped/Manual Start]
  <C:\windows\System32\svchost.exe -k netsvcs-->C:\WINDOWS\System32\mspmsnsv.dll><Microsoft Corporation>
gototop
 
12   1  /  2  页   跳转
页面顶部
Powered by Discuz!NT